
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@pressa/cli
Advanced tools
Command-line interface for Pressa - Compile-as-a-Service. LaTeX in, PDF out.
npm install -g @pressa/cli
# Set your API key
pressa auth
# Compile a LaTeX file
pressa compile report.tex
# Compile with a specific engine
pressa compile report.tex --compiler xelatex
# Read from stdin
cat report.tex | pressa compile -
# JSON output (for AI agents)
pressa compile report.tex --json
pressa authConfigure your API key.
# Interactive
pressa auth
# Non-interactive
pressa auth --key pressa_xxxx
pressa compile <file>Compile a LaTeX file to PDF.
| Option | Description |
|---|---|
-c, --compiler | LaTeX compiler: pdflatex (default), xelatex, or lualatex (Pro and Business plans only) |
-o, --output | Output PDF filename |
--json | Machine-readable JSON output |
--no-download | Don't download PDF, just return URL |
-a, --asset | Include a local asset file (repeatable). logo.png or logo.png=/path/to/file.png |
-s, --stored-asset | Reference a stored asset by name from the library (repeatable) |
-u, --url | API base URL override |
Use - as filename to read from stdin.
The file must be LaTeX source code (containing \documentclass, \begin{document}, \input{}, or \include{}). Pressa is a LaTeX compiler, not a text-to-PDF converter. The CLI prints a yellow warning if the file does not look like LaTeX, and the server rejects non-LaTeX input with not_latex_source even if the warning is ignored. To produce a PDF from plain text or markdown, ask an AI agent to generate LaTeX from your content first.
Each plan has limits on pages per document, LaTeX source size, PDF output size, and compile timeout. If a compile exceeds your plan's page limit, the document does not count against your monthly quota and the CLI prints the limit and an upgrade URL.
pressa assets (Asset Library)Manage a persistent library of assets (logos, signatures, images) that can be referenced by name across compiles. Requires a paid plan (Starter or above).
# List stored assets and quota
pressa assets list
# Upload a file (uses the basename by default)
pressa assets upload ./logo.png
# Upload under a different name
pressa assets upload ./brand-logo.png --name logo.png
# Download an asset back to disk
pressa assets get logo.png --output ./logo.png
# Print metadata as JSON (no binary content)
pressa assets get logo.png --json
# Delete (asks for confirmation unless --yes)
pressa assets delete logo.png --yes
Use stored assets in a compile by name (skips re-uploading large files on every request):
pressa compile invoice.tex --stored-asset logo.png --stored-asset signature.png
--stored-asset is repeatable and can be combined with inline --asset flags. A name cannot appear in both at the same time.
pressa usageShow your API usage statistics.
Plan: free
Used: 3/50 this month
Resets: April 30, 2026
API Key: pressa_c... (Test Key)
Config is stored in ~/.pressa/config.json:
{
"api_key": "pressa_xxxx",
"api_url": "https://api.pressa.dev"
}
cd cli
npm install
npm run build
npm run dev # watch mode
MIT
FAQs
CLI for Pressa - Compile-as-a-Service. LaTeX in, PDF out.
The npm package @pressa/cli receives a total of 10 weekly downloads. As such, @pressa/cli popularity was classified as not popular.
We found that @pressa/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.